Trend hit by UPX vulnerability

Compression handling issue affects swathe of products.

A wide range of Trend Micro security products are affected by a flaw in the handling of files compressed with UPX, which could be exploited to shut down the product or even access a machine remotely. An update is available to circumvent the problem.

ISSD 2010 conference

The buffer overflow vulnerability was pointed out to Trend in mid-January, and has now been disclosed following the release of a pattern file to fix the hole. Affected products include flagship OfficeScan and PC-cillin scanners, as well as various mail and network security products including Linux and NetWare offerings.

Trend's announcement of the problem, along with the fix, is available here. An alert from iDefense is here, and another from Secunia here.

A second and less significant vulnerability, exploitable only from the local system, has also been reported in the Anti-Rootkit module included in several Trend products. This flaw has also been fixed with an upgrade, and details are again available from Trend, iDefense or Secunia. Trend users are advised to ensure both fixes are applied as soon as possible.

08 February 2007

Tags:    del.icio.us  digg this! digg this


Poll

Do you use the same password(s) across multiple websites?
I use the same password for all sites
I have a number of passwords but use the same for some sites
I use a different password for each site
I don't sign up to any sites that require a password

Leave a comment
View 4 comments

Jobs Recruit Sidebar

VB2010

VB2010 VB2010 will take place 29 September-1 October 2009 at the Westin Bayshore, Vancouver, BC, Canada. Early bird discount available until 15th June 2010.
Virus Bulletin currently has 190,635 registered users.